My main use case for CyberArk Secure Cloud Access is that we have multiple clusters. We use CyberArk Secure Cloud Access with one of our clusters to reduce the attack surfaces, so a user cannot get access to the full network, and access is specific to approved resources. It also provides single sign-on as well as Zero Trust Network Access, which is called ZTNA.
In my day-to-day work, single sign-on and Zero Trust Network Access function as follows: instead of opening the whole corporate network through any VPN, CyberArk gives only specific applications or systems. For example, a developer only gets access to a particular Kubernetes or OpenShift cluster or any particular applications or database, not the full internal network, which reduces security risk significantly.
I would add that CyberArk Secure Cloud Access gives IT-based access control, privileged access protections, session monitoring, and recording. These are the most important features and use cases that we are using.